Mmastodon TechnologyCybersecurity first seen 19 h ago, last 19 h ago, peak #5
Hackers Abuse Microsoft Power BI to Deploy Rogue Remote Access Tools
Original: (huntress.com) Threat Actors Abuse Microsoft Power BI in Phishing Campaign to Deploy Rogue ScreenConnect RMM Clients In
Security firm Huntress reports a phishing campaign in which attackers abuse legitimate Microsoft Power BI domains to bypass email security filters and trick users into installing rogue ScreenConnect remote monitoring and management clients. Because the malicious links come from trusted Microsoft infrastructure, they evade common detection methods. Cybersecurity researchers are warning organizations to scrutinize Power BI sharing invitations and monitor for unauthorized ScreenConnect installations.
Why now: The abuse of trusted Microsoft domains to deliver remote access malware is a novel and concerning phishing technique.
HuntressMicrosoft Power BIScreenConnect
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/1364607